1. Platform controls
SwiftBizness uses role-aware routes, protected server handlers, Supabase data separation, audit logs, request rate limiting, bot and abuse checks, staff account validation, work-hour restrictions, API key hashing, scoped API access, and security headers.
Financial and high-impact actions such as payment approval, referral approval, payout recording, rejected referral override, and duplicate merge review require authorized business access.
Public APIs are designed for ingestion and draft creation. External websites should not be able to approve payments, approve referrals, issue refunds, delete customers, or modify commissions.